CVE-2023-37389 HIGH

CVE-2023-37389: WordPress Booking Package SAASPROJECT plugin <= 1.5.98 - Unauthenticated Privilege Escalation vulnerability

Vendor Saasproject Booking Package
Product Booking Package
Weakness CWE-269
Published May 17, 2024
Last update April 28, 2026

CVSS base score

8.8/10
Attack vector Network
Attack complexity Low
Privileges required None
User interaction Required
Confidentiality High
Integrity High

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

What the vulnerability does

01Description

Improper Privilege Management vulnerability in SAASPROJECT Booking Package Booking Package allows Privilege Escalation.This issue affects Booking Package: from n/a through 1.5.98.

Explanation of Vulnerability in Simple Terms

02Summary

The Booking Package contains a privilege management flaw that allows an unauthenticated attacker to gain unauthorized access to sensitive functions. The vulnerability requires user interaction, such as clicking a malicious link. An attacker can read, modify, or delete booking data and other site information. All versions up to 1.5.98 are affected.

What an attacker can do

03Attacker Capabilities

Read, modify, or delete booking data and other sensitive site information without authorization.

Potential impact on your site

04Site Impact

Booking records, customer data, and site functionality can be compromised without authentication.

Conditions required to exploit

05Prerequisites

Attacker must trick a user into clicking a malicious link or visiting a crafted page.

Key dates

06Disclosure timeline

May 17, 2024 CVE published
April 28, 2026 Record updated

Related vulnerabilities

08Related CVE